Accounting Information Systems, 2e (Kay/Ovlia)
Chapter 11 Cybersecurity
Objective 1
1) Cybersecurity combines people, processes, and technology to continually monitor
vulnerabilities and respond proactively to secure the system.
2) Personal data, such as home address and credit card number, are stored on hotel card keys.
3) ________ developed the 10-domain Common Body of Knowledge (CBK) for IT security and
controls.
4) Which of the following is NOT part of the 10 domains of cybersecurity?
A) Cryptography
B) Database security
C) Physical and environmental security
D) Access control
5) List the 10 domains that comprise the 10-domain Common Body of Knowledge (CBK).
Objective 2
1) Most data thieves are professional criminals deliberately trying to steal information they can
turn into cash.
2) While dumpster diving is unethical, it may not be illegal.
3) Phishing involves attempts to obtain passwords by sniffing messages sent between computers
on the network.
4) Laws related to cybersecurity originate from legislation, regulations, and case law.
5) Successful data breaches never involves multiple means of attach.
6) ________ are crimes connected to information assets and IT.
7) ________ relates to the laws and regulations to prevent, investigate, and prosecute
cybercrimes.
8) ________ refers to rummaging through garbage for discarded documents or digital media.
9) ________ involves attempts to obtain passwords by sniffing messages sent between
computers on the network.
10) ________ involves collecting, examining, and preserving evidence of cybercrimes.
Match the legislation to the description.
A) This legislation requires organizations that handle credit and debit card data to meet
cybersecurity requirements to safeguard the data.
B) Frank-Dodd Wall Street Reform and Consumer Protection Act
C) This legislation requires each federal agency to develop, document, and implement an
agency-wide information security program.
D) This legislation requires proper internal control, including information security and controls.
E) Federal Privacy Act of 1974
F) This legislation requires financial institutions to provide customers with privacy notices and
prohibits the institutions from sharing customer information with nonaffiliated third parties.
11) Sarbanes-Oxley (SOX)
Diff: 2
Objective: Q11.2 What are cyberlaw and cybercrime?
12) Gramm-Leach-Bliley Act
Diff: 2
Objective: Q11.2 What are cyberlaw and cybercrime?
13) Payment Card Industry Data Security Standards
Diff: 2
Objective: Q11.2 What are cyberlaw and cybercrime?
14) Federal Information Security Management Act (FISMA)
Diff: 2
Objective: Q11.2 What are cyberlaw and cybercrime?
15) Cybercrimes are crimes connected to what? (Select the best answer)
A) Information assets and IT
B) The financial services industry
C) Electronic payments
D) Electronic transfer of funds
16) According to Verizon’s 2012 Data Breach Investigations Report, what percentage of
breaches were tied to organized criminal groups?
A) 79%
B) 65%
C) 83%
D) 58%
17) According to Verizon’s 2012 Data Breach Investigations Report, what percentage of attacks
were from activist groups?
A) 63%
B) 58%
C) 52%
D) 48%
18) According to Verizon’s 2012 Data Breach Investigations Report, what percentage of
breaches were physical attacks, such as a stolen laptop?
A) 10%
B) 15%
C) 23%
D) 45%
19) Which legislation requires financial institutions to provide customers with privacy notices
and prohibits the institutions from sharing customer information with nonaffiliated third parties?
A) Federal Privacy Act of 1974
B) Sarbanes-Oxley
C) Gramm-Leach-Bliley Act
D) Computer Security Act of 1987
20) Which legislation requires each federal agency to develop, document, and implement an
agency-wide information security program?
A) Employee Privacy Issues
B) Federal Information Security Management Act of 2002 (FISMA)
C) Computer Fraud and Abuse Act
D) Federal Privacy Act of 1974
21) Which legislation requires organizations that handle credit and debit card data to meet
cybersecurity requirements to safeguard data?
A) Computer Fraud and Abuse Act
B) Federal Information Security Management Act of 2002 (FISMA)
C) Economic Espionage Act of 1996
D) Payment Card Industries Data Security Standards (PCI-DDS)
22) It is the first day of your new job as an accounting intern. In the elevator on the way to your
cubicle, a gentleman in the elevator (that you later learn is the controller of the company) says to
you, “A salami attack.” Shaking his head, he repeats, “It sounds more like someone being hit
over the head with a sausage. It’s just a small amount, so why should we care? You are our new
intern, aren’t you? Well, why don’t you send me an email by this afternoon explaining what is a
salami attack and why we should prevent them.”
1) The information security principle integrity ensures that sensitive data at each point in
information processing is secure and protected from unauthorized access.
2) This security management principle ensures that sensitive data at each point in information
processing is secure and protected from unauthorized access.
A) Confidentiality
B) Integrity
C) Private
D) Availability
3) In the government sector, unauthorized disclosure of data with this classification might be
harmful to national security.
A) Sensitive But Unclassified
B) Top Secret
C) Confidential
D) Secret
4) Data ________ is a security principle that ensures data is accurate and reliable.
5) List and define the information sensitivity classifications for the private sector.
6) List and define information sensitivity classification for governmental sector.
7) Provide example of how security and controls measures can be included in the planning,
design, installation, and deployment phases of the SDLC.
8) List and describe three frameworks that provide a conceptual structure to address security and
control.
1) Wide area networks (WANs) cover a large geographic region, such as the lower Midwest.
2) The Internet is a collection of many networks of various types, connecting different LANs
MANs, and WANs together.
3) Bridges connect LANs of similar or different types to create an intranet.
4) Enterprise security architecture studies the enterprise architecture and business environment to
develop an overall strategy and plan that best fits enterprise-specific needs.
5) ________ is a piece of computer hardware that extracts instructions and data and decodes and
executes the instructions.
6) ________ are types of computer hardware that capture data from various sources and move
the data into main memory.
7) When application software is updated to fix an error or add a new feature, a section of coding
called a ________ is inserted into the program.
Match the network protocol with the appropriate definition.
A) A software program that provides message transportation services between sending and
receiving computers
B) A software program commonly used to connect computers to create a LAN
C) A software program that provides routing services to messages transmitted over the Internet
D) A software program that allows the enterprise network to connect to the network of vendors
and suppliers through proprietary lines
8) Ethernet protocol
Diff: 2
Objective: Q11.4 What is security architecture and design?
9) Internet protocol (IP)
Diff: 1
Objective: Q11.4 What is security architecture and design?
10) Transport control protocol (TCP)
Diff: 2
Objective: Q11.4 What is security architecture and design?
11) Electronic data interchange (EDI)
Diff: 2
Objective: Q11.4 What is security architecture and design?
12) What is a microcomputer?
A) A computer with moderate computing power
B) A personal computer or laptop
C) A smart phone
D) A powerful, high-speed computer used for complex numerical calculations
13) Which of the following network hardware are typically personal computers and laptops
connected to the network?
A) Workstation computers
B) Server computers
C) Routing devices
D) Peripherals
14) Which of the following network hardware are utility devices connected to the network for
shared use?
A) Workstation computers
B) Server computers
C) Routing devices
D) Peripherals
15) Which network protocol (software) allows the enterprise network to connect to the network
of vendors and suppliers through proprietary lines?
A) Transport control protocol (TCP)
B) Ethernet protocol
C) Internet protocol (IP)
D) Electronic data interchange (EDI)
16) Which network protocol (software) is commonly used to connect computers to create a
LAN?
A) Internet protocol (IP)
B) Ethernet protocol
C) Electronic data interchange (EDI)
D) Transport control protocol (TCP)
17) Security of the IT architecture should be considered in which phase of the system
development life cycle (SDLC)?
A) All the phases
B) Design phase
C) Install phase
D) Build/purchase phase
18) In IT architecture security, what is NOT part of the software application ring?
A) Accounting software
B) Web browsers
C) Word processing applications
D) Relational database management system
19) What are the basic hardware components of a computer?
20) List and describe four types of network software protocols.
21) Securing computer architecture involves three rings of protection. What is in each ring?
Provide examples.
1) Telecommunications, networks, and the internet all relate to data transmission.
2) ________ is a network used by external customers and/or suppliers.
3) Network cyberattacks typically target ________ because they offer access to the network.
4) ________ firewall is a special type of firewall located on a server used to intercept and inspect
all incoming messages prior to delivering them to the intended recipients.